
New LegacyHive PoC Sparks Windows Privilege Escalation Talk After Patch Tuesday
Security researcher Chaotic Eclipse released LegacyHive, a PoC for a Windows User Profile Service privilege-escalation vulnerability. The PoC reportedly requires an extra standard credential and a third username (potentially an admin) and, if successful, mounts the target user hive in the current user classes root; the exploit is claimed to work on all supported Windows editions, including the July 2026 Patch Tuesday versions. The disclosure comes amid a disputed back-and-forth with Microsoft, ongoing Defender flaws, and a wave of Patch Tuesday fixes, notably for SharePoint Server, with CISA listing several flaws as actively exploited. The piece highlights growing turbulence around Patch Tuesday disclosures in 2026.